Ensure that the AD FS service account is provided access to the SSL, token signing, and token decryption certificates stored ...

Ensure that the AD FS service account is provided access to the SSL, token signing, and token decryption certificates stored in the local computer certificate store.

  1. From Command Line type MMC.
  2. Go to File->Add/Remove Snap-In
  3. Select Certificates and click Add. -> Select Computer Account and click Next. -> Select Local Computer and click Finish. Click OK.

Open Certificates(Local Computer)/Personal/Certificates.For all the certificates that are used by AD FS:
  1. Right click on the certificate.
  2. Select All Tasks -> Manage Private Keys.
  3. On the Security Tab under Group or user names ensure that the adfs service account is present. If not select Add and add the AD FS service account.
  4. Select the AD FS service account and under "Permissions for " make sure Read permission is allowed (check mark).